FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu()
Published Jul 24, 2026
7.1
HIGHCVSS 4.0
EPSS 0.35%
Description
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing.
Affected products
-
Affected
- ≥ 0, ≤ 8.1.2
-
Unaffected
No data.
Red Hat Enterprise Linux AI (RHEL AI) 3
ffmpeg
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-aws-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-azure-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-azure-rocm-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gcp-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-vllm-gaudi-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux AI (RHEL AI) 3 | ffmpeg | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-aws-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-azure-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-azure-rocm-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gcp-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-vllm-gaudi-rhel9 | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-66037 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2506911 Issue Tracking
- https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5 patch
- https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627 issue-trackingIssue TrackingPatch
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48739 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-66037
- https://www.cve.org/CVERecord?id=CVE-2026-66037
- https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-66037 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2506911 | Issue Tracking | |
| https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5 | patch | |
| https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627 | issue-trackingIssue TrackingPatch | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48739 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-66037 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-66037 | ||
| https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data